Hi Clint
I did a search using Regscan with the term blank.htm and these are my results:
Windows Registry Editor Version 5.00
; Regscan.vbs Version: 1.2 by rand1038
; 8/23/2006 2:35:43 PM
; Search Term(s) Used: "blank.htm"
; 5 matches were found.
; The search took 29 seconds.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
"blank"="res://mshtml.dll/blank.htm"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Outlook Express\5.0\Default Settings\Recent Stationery List]
"File5"="Blank.htm"
[HKEY_USERS\S-1-5-21-1547161642-507921405-854245398-1003\Identities\{EF1DA7B1-EB88-4AEF-BE3E-8E1BA16AEF0F}\Software\Microsoft\Outlook Express\5.0\Recent Stationery List]
"File5"="Blank.htm"
[HKEY_USERS\S-1-5-21-1547161642-507921405-854245398-1003\Identities\{EF1DA7B1-EB88-4AEF-BE3E-8E1BA16AEF0F}\Software\Microsoft\Outlook Express\5.0\Recent Stationery Wide List]
"File5"="Blank.htm"
[HKEY_USERS\S-1-5-21-1547161642-507921405-854245398-1003\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
=============
Let's see what you get please.
Regscan
Please download
RegScan .
Within RegScan.zip you will find the file regscan.vbs
You may have to allow this script to run or disable anti-spyware again in order for it to run.
A window will open titled RegFinder.vbs and you will see place to input search terms.
Please enter the search terms:
blank.htm
After the search has completed a window titled Results.txt will open.
Please copy the results and post(reply) back
RegScan results below; what do you make of the dnserror?
Windows Registry Editor Version 5.00
; Regscan.vbs Version: 1.2 by rand1038
; 8/23/2006 2:14:07 PM
; Search Term(s) Used: "blank.htm"
; 6 matches were found.
; The search took 53 seconds.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
"blank"="res://mshtml.dll/blank.htm"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Outlook Express\5.0\Default Settings\Recent Stationery List]
"File5"="Blank.htm"
[HKEY_USERS\S-1-5-21-1343024091-113007714-839522115-1003\Identities\{8EFEF887-9D71-4844-94D3-61BC9643768A}\Software\Microsoft\Outlook Express\5.0\Recent Stationery List]
"File5"="Blank.htm"
[HKEY_USERS\S-1-5-21-1343024091-113007714-839522115-1003\Software\Google\NavClient\1.1\History]
"%System Root%\\system32\\blank.htm"=hex:99,9e,ec,44
"%SystemRoot%\\system32\\blank.htm"=hex:1b,a0,ec,44
[HKEY_USERS\S-1-5-21-1343024091-113007714-839522115-1003\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
Hi Clint
Let's try the following:
STEP 1.
======
Hoster
Please download
hoster .
Unzip Hoster.zip Open Hoster.exe. Then click on "Restore Original Hosts" Close program when complete. Empty Recycle Bin
Do you have your Windows installation CD? I would like you to try the IEFIX.
http://windowsxp.mvps.org/IEFIX.htm
I did Hoster. It did not seem to do anything. We have done the IEFix before and it helped for about 30 minutes, then everything slowed down again. I will re-run it and see what happens.
Susan,
Hoster seems to have helped. Something is still trying to alter the host connection. Not sure how we get rid of it totally, but at least my computer is usable. How do we find whatever is trying to change the host connection?
Hi Clint,
I am glad to hear that there is some improvement. I am seeking more help with your log.
Pop-ups are always about:blank and nothing else?
Please explain about the something is trying to alter the host connection. Are you getting alerts from firewall or something?
Something is still trying to alter the host connection.
yes, about:blank. The firewall icon, at bottom righthand corner, will have a bubble that states there are conflicting IP connections; essentially something is trying to change my connection. Wish I knew technical terms better.
Hello Clint,
If you run Adaware again, is everything cleaned or quarantined?
Does this still exist if you run adaware again?
IEHIjacker.SearchExe(TAC index:6):3 total references
Also you have two antivirus applications running-AVG and McAfee.
You should only have one running because they can interfere with each other. Therefore you need to uninstall one.
Please let me know about Adaware.
Susan,
I will run AE twice. What happens as of now is everyday the same tracking cookies latch onto my connection and slow it down. Will post the results.
Are you still having problems?
Susan,
I have pasted the Ad Log. Essentially, everyday these same data miners return.
Ad-Aware SE Build 1.06r1
Logfile Created on:Monday, September 25, 2006 3:01:28 PM
Created with Ad-Aware SE Personal, free for private use.
Using definitions file:SE1R124 19.09.2006
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
References detected during the scan:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Tracking Cookie(TAC index:3):17 total references
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Definition File:
=========================
Definitions File Loaded:
Reference Number : SE1R124 19.09.2006
Internal build : 152
File location : C:\Program Files\Spy and Ad ware Software\Ad-Aware SE Personal
\defs.ref
File size : 790565 Bytes
Total size : 2559852 Bytes
Signature data size : 2510913 Bytes
Reference data size : 48427 Bytes
Signatures total : 68975
CSI Fingerprints total : 3884
CSI data size : 159891 Bytes
Target categories : 15
Target families : 983
Memory + processor status:
==========================
Number of processors : 1
Processor architecture : Intel Pentium IV
Memory available:27 %
Total physical memory:260096 kb
Available physical memory:69232 kb
Total page file size:640000 kb
Available on page file:305976 kb
Total virtual memory:2097024 kb
Available virtual memory:2041816 kb
OS:Microsoft Windows XP Home Edition Service Pack 2 (Build 2600)
Ad-Aware SE Settings
===========================
Set : Search for low-risk threats
Set : Safe mode (always request confirmation)
Set : Don't log streams smaller than 0 Bytes
Set : Scan active processes
Set : Scan registry
Set : Deep-scan registry
Set : Scan my IE Favorites for banned URLs
Set : Scan within archives
Set : Scan my Hosts file
Extended Ad-Aware SE Settings
===========================
Set : Unload recognized processes & modules during scan
Set : Scan registry for all users instead of current user only
Set : Always try to unload modules before deletion
Set : During removal, unload Explorer and IE if necessary
Set : Let Windows remove files in use at next reboot
Set : Delete quarantined objects after restoring
Set : Include basic Ad-Aware settings in log file
Set : Include additional Ad-Aware settings in log file
Set : Include reference summary in log file
Set : Include alternate data stream details in log file
Set : Play sound at scan completion if scan locates critical objects
9-25-2006 3:01:28 PM - Scan started. (Full System Scan)
Listing running processes
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
#:1 [smss.exe]
FilePath : \SystemRoot\System32\
ProcessID : 540
ThreadCreationTime : 9-25-2006 3:29:35 PM
BasePriority : Normal
#:2 [csrss.exe]
FilePath : \??\C:\WINDOWS\system32\
ProcessID : 612
ThreadCreationTime : 9-25-2006 3:29:37 PM
BasePriority : Normal
#:3 [winlogon.exe]
FilePath : \??\C:\WINDOWS\system32\
ProcessID : 636
ThreadCreationTime : 9-25-2006 3:29:38 PM
BasePriority : High
#:4 [services.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 680
ThreadCreationTime : 9-25-2006 3:29:38 PM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Services and Controller app
InternalName : services.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : services.exe
#:5 [lsass.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 692
ThreadCreationTime : 9-25-2006 3:29:39 PM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : LSA Shell (Export Version)
InternalName : lsass.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : lsass.exe
#:6 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 844
ThreadCreationTime : 9-25-2006 3:29:40 PM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:7 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 908
ThreadCreationTime : 9-25-2006 3:29:40 PM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:8 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1004
ThreadCreationTime : 9-25-2006 3:29:41 PM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:9 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1060
ThreadCreationTime : 9-25-2006 3:29:41 PM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:10 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1096
ThreadCreationTime : 9-25-2006 3:29:41 PM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:11 [lexbces.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1416
ThreadCreationTime : 9-25-2006 3:29:44 PM
BasePriority : Normal
FileVersion : 7.4
ProductVersion : 7.4
ProductName : MarkVision for Windows (32 bit)
CompanyName : Lexmark International, Inc.
FileDescription : LexBce Service
InternalName : LexBce Service
LegalCopyright : © 1993 - 2002 Lexmark International, Inc.
OriginalFilename : LexBceS.exe
#:12 [lexpps.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1584
ThreadCreationTime : 9-25-2006 3:29:44 PM
BasePriority : Normal
FileVersion : 7.4
ProductVersion : 7.4
ProductName : MarkVision for Windows (32 bit)
CompanyName : Lexmark International, Inc.
FileDescription : LEXPPS.EXE
InternalName : LEXPPS
LegalCopyright : © 1993 - 2002 Lexmark International, Inc.
OriginalFilename : LEXPPS.EXE
Comments : MarkVision for Windows '95 New P2P Server (32-bit)
#:13 [spoolsv.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1592
ThreadCreationTime : 9-25-2006 3:29:44 PM
BasePriority : Normal
FileVersion : 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)
ProductVersion : 5.1.2600.2696
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Spooler SubSystem App
InternalName : spoolsv.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : spoolsv.exe
#:14 [explorer.exe]
FilePath : C:\WINDOWS\
ProcessID : 1628
ThreadCreationTime : 9-25-2006 3:29:45 PM
BasePriority : Normal
FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 6.00.2900.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows Explorer
InternalName : explorer
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : EXPLORER.EXE
#:15 [hkcmd.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1844
ThreadCreationTime : 9-25-2006 3:29:48 PM
BasePriority : Normal
FileVersion : 3.0.0.4342
ProductVersion : 7.0.0.4342
ProductName : Intel® Common User Interface
CompanyName : Intel Corporation
FileDescription : hkcmd Module
InternalName : HKCMD
LegalCopyright : Copyright 1999-2004, Intel Corporation
OriginalFilename : HKCMD.EXE
#:16 [bcmsmmsg.exe]
FilePath : C:\WINDOWS\
ProcessID : 1852
ThreadCreationTime : 9-25-2006 3:29:48 PM
BasePriority : Normal
FileVersion : 3.5.25 08/27/2003 20:04:35
ProductVersion : 3.5.25 08/27/2003 20:04:35
ProductName : BCM Modem Messaging Applet
CompanyName : Broadcom Corporation
FileDescription : Modem Messaging Applet
InternalName : smdmstat.exe
LegalCopyright : Copyright © Broadcom Corporation 1998-2000
OriginalFilename : smdmstat.exe
#:17 [lxbbbmgr.exe]
FilePath : C:\Program Files\Lexmark X74-X75\
ProcessID : 1868
ThreadCreationTime : 9-25-2006 3:29:48 PM
BasePriority : Normal
FileVersion : 1.0.5.0
ProductVersion : 1.0.5.0
ProductName : Button Manager Executable
CompanyName : Lexmark International, Inc.
FileDescription : Lexmark X74-X75 Button Manager
InternalName : lxbbbmgr.exe
LegalCopyright : © 2002 Lexmark International, Inc.
OriginalFilename : lxbbbmgr.exe
#:18 [qttask.exe]
FilePath : C:\Program Files\QuickTime\
ProcessID : 1876
ThreadCreationTime : 9-25-2006 3:29:48 PM
BasePriority : Normal
FileVersion : 6.5.1
ProductVersion : QuickTime 6.5.1
ProductName : QuickTime
CompanyName : Apple Computer, Inc.
InternalName : QuickTime Task
LegalCopyright : © Apple Computer, Inc. 2001-2004
OriginalFilename : QTTask.exe
#:19 [ituneshelper.exe]
FilePath : C:\Program Files\iTunes\
ProcessID : 1892
ThreadCreationTime : 9-25-2006 3:29:48 PM
BasePriority : Normal
FileVersion : 4.8.0.31
ProductVersion : 4.8.0.31
ProductName : iTunes
CompanyName : Apple Computer, Inc.
FileDescription : iTunesHelper Module
InternalName : iTunesHelper
LegalCopyright : © 2003-2005 Apple Computer, Inc. All Rights Reserved.
OriginalFilename : iTunesHelper.exe
#:20 [lxbbbmon.exe]
FilePath : C:\Program Files\Lexmark X74-X75\
ProcessID : 1912
ThreadCreationTime : 9-25-2006 3:29:49 PM
BasePriority : Normal
FileVersion : 1.0.5.0
ProductVersion : 1.0.5.0
ProductName : Button Monitor Executable
CompanyName : Lexmark International, Inc.
FileDescription : Lexmark X74-X75 Button Monitor
InternalName : lxbbbmon.exe
LegalCopyright : © 2002 Lexmark International, Inc.
OriginalFilename : lxbbbmon.exe
#:21 [winpatrol.exe]
FilePath : C:\PROGRA~1\BILLPS~1\WINPAT~1\
ProcessID : 1920
ThreadCreationTime : 9-25-2006 3:29:49 PM
BasePriority : Normal
FileVersion : 9, 7, 4, 0
ProductVersion : 9.7.4.0
ProductName : WinPatrol Monitor
CompanyName : BillP Studios
FileDescription : WinPatrol System Monitor
InternalName : WinPatrol Monitor
LegalCopyright : Copyright © 1997- 2005 BillP Studios
OriginalFilename : Scotty
Comments : Let Scotty the Windows Watchdog patrol your system.
#:22 [avgcc.exe]
FilePath : C:\PROGRA~1\Grisoft\AVG7\
ProcessID : 1976
ThreadCreationTime : 9-25-2006 3:29:49 PM
BasePriority : Normal
FileVersion : 7,1,0,404
ProductVersion : 7.1.0.404
ProductName : AVG Anti-Virus System
CompanyName : GRISOFT, s.r.o.
FileDescription : AVG Control Center
InternalName : AvgCC
LegalCopyright : Copyright © 2006, GRISOFT, s.r.o.
OriginalFilename : AvgCC.EXE
#:23 [mm_tray.exe]
FilePath : C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\
ProcessID : 1996
ThreadCreationTime : 9-25-2006 3:29:50 PM
BasePriority : Normal
FileVersion : 7.10.4053
ProductVersion : 7.10.4053
ProductName : MUSICMATCH JUKEBOX
CompanyName : MUSICMATCH, Inc.
FileDescription : mm_tray
InternalName : mm_tray
LegalCopyright : Copyright © MUSICMATCH 1998-2001
LegalTrademarks :
OriginalFilename : mm_tray.exe
#:24 [j2gdllcmd.exe]
FilePath : C:\Program Files\eFax Messenger 4.0\
ProcessID : 2036
ThreadCreationTime : 9-25-2006 3:29:50 PM
BasePriority : Normal
FileVersion : 4.0.134.0
ProductVersion : 4.0.134.0
ProductName : eFax Messenger ™
CompanyName : j2 Global Communications, Inc.
FileDescription : eFax Messenger - DLL Command Utility
InternalName : DllCmd32
LegalCopyright : Copyright © 2005 j2 Global Communications, Inc.
LegalTrademarks : eFax®
eFax.com ™
eFax Messenger ™
eFax Messenger Plus ™
JetSuite®
PaperMaster Pro ™
OriginalFilename : DllCmd32.exe
#:25 [j2gtray.exe]
FilePath : C:\Program Files\eFax Messenger 4.0\
ProcessID : 2044
ThreadCreationTime : 9-25-2006 3:29:50 PM
BasePriority : Normal
FileVersion : 4.0.134.0
ProductVersion : 4.0.134.0
ProductName : eFax Messenger ™
CompanyName : j2 Global Communications, Inc.
FileDescription : eFax Messenger - Tray
InternalName : HotTray
LegalCopyright : Copyright © 2005 j2 Global Communications, Inc.
LegalTrademarks : eFax®
eFax.com ™
eFax Messenger ™
eFax Messenger Plus ™
JetSuite®
PaperMaster Pro ™
OriginalFilename : HotTray.exe
#:26 [avgamsvr.exe]
FilePath : C:\PROGRA~1\Grisoft\AVG7\
ProcessID : 240
ThreadCreationTime : 9-25-2006 3:29:53 PM
BasePriority : Normal
FileVersion : 7,1,0,364
ProductVersion : 7.1.0.364
ProductName : AVG Anti-Virus System
CompanyName : GRISOFT, s.r.o.
FileDescription : AVG Alert Manager
InternalName : avgamsvr
LegalCopyright : Copyright © 2005, GRISOFT, s.r.o.
OriginalFilename : avgamsvr.EXE
#:27 [avgupsvc.exe]
FilePath : C:\PROGRA~1\Grisoft\AVG7\
ProcessID : 264
ThreadCreationTime : 9-25-2006 3:29:53 PM
BasePriority : Normal
FileVersion : 7,0,0,346
ProductVersion : 7.0.0.346
ProductName : AVG 7.0 Anti-Virus System
CompanyName : GRISOFT, s.r.o.
FileDescription : AVG Update Service
InternalName : avgupsvc
LegalCopyright : Copyright © 2005, GRISOFT, s.r.o.
OriginalFilename : avgupdsvc.EXE
#:28 [guard.exe]
FilePath : C:\Program Files\ewido anti-spyware 4.0\
ProcessID : 308
ThreadCreationTime : 9-25-2006 3:29:53 PM
BasePriority : Normal
FileVersion : 4, 0, 0, 172
ProductVersion : 4, 0, 0, 172
ProductName : ewido anti-spyware
CompanyName : Anti-Malware Development a.s.
FileDescription : ewido anti-spyware guard
InternalName : ewido anti-spywareguard
LegalCopyright : Copyright © 2005 Anti-Malware Development a.s.
OriginalFilename : guard.exe
#:29 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 332
ThreadCreationTime : 9-25-2006 3:29:58 PM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:30 [wdfmgr.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 960
ThreadCreationTime : 9-25-2006 3:29:58 PM
BasePriority : Normal
FileVersion : 5.2.3790.1230 built by: dnsrv(bld4act)
ProductVersion : 5.2.3790.1230
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows User Mode Driver Manager
InternalName : WdfMgr
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : WdfMgr.exe
#:31 [spysweeper.exe]
FilePath : C:\Program Files\Webroot\Spy Sweeper\
ProcessID : 1092
ThreadCreationTime : 9-25-2006 3:29:59 PM
BasePriority : Normal
FileVersion : 3,0,5,1286
ProductVersion : 3, 0
ProductName : Spy Sweeper SDK
CompanyName : Webroot Software, Inc.
FileDescription : Spy Sweeper Engine
LegalCopyright : Copyright © 2002 - 2006, All Rights Reserved.
LegalTrademarks : Spy Sweeper is a trademark of Webroot Software, Inc.
OriginalFilename : SpySweeper.exe
#:32 [avgfwsrv.exe]
FilePath : C:\PROGRA~1\Grisoft\AVG7\
ProcessID : 1508
ThreadCreationTime : 9-25-2006 3:30:03 PM
BasePriority : Normal
FileVersion : 7,1,0,406
ProductVersion : 7.1.0.406
ProductName : AVG Anti-Virus System
CompanyName : GRISOFT, s.r.o.
FileDescription : AVG Firewall Service
InternalName : avgfwsrv
LegalCopyright : Copyright © 2006, GRISOFT, s.r.o.
OriginalFilename : avgfwsrv.exe
#:33 [ipodservice.exe]
FilePath : C:\Program Files\iPod\bin\
ProcessID : 1652
ThreadCreationTime : 9-25-2006 3:30:05 PM
BasePriority : Normal
FileVersion : 4.8.0.31
ProductVersion : 4.8.0.31
ProductName : iTunes
CompanyName : Apple Computer, Inc.
FileDescription : iPodService Module
InternalName : iPodService
LegalCopyright : © 2003-2005 Apple Computer, Inc. All Rights Reserved.
OriginalFilename : iPodService.exe
#:34 [alg.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 2380
ThreadCreationTime : 9-25-2006 3:30:07 PM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Application Layer Gateway Service
InternalName : ALG.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : ALG.exe
#:35 [firefox.exe]
FilePath : C:\Program Files\Mozilla Firefox\
ProcessID : 3292
ThreadCreationTime : 9-25-2006 3:34:35 PM
BasePriority : Normal
#:36 [excel.exe]
FilePath : C:\Program Files\Microsoft Office\Office10\
ProcessID : 3896
ThreadCreationTime : 9-25-2006 3:46:46 PM
BasePriority : Normal
#:37 [iexplore.exe]
FilePath : C:\Program Files\Internet Explorer\
ProcessID : 820
ThreadCreationTime : 9-25-2006 9:49:41 PM
BasePriority : Normal
FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 6.00.2900.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Internet Explorer
InternalName : iexplore
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : IEXPLORE.EXE
#:38 [ad-aware.exe]
FilePath : C:\Program Files\Spy and Ad ware Software\Ad-Aware SE Personal\
ProcessID : 3448
ThreadCreationTime : 9-25-2006 10:00:59 PM
BasePriority : Normal
FileVersion : 6.2.0.236
ProductVersion : SE 106
ProductName : Lavasoft Ad-Aware SE
CompanyName : Lavasoft Sweden
FileDescription : Ad-Aware SE Core application
InternalName : Ad-Aware.exe
LegalCopyright : Copyright © Lavasoft AB Sweden
OriginalFilename : Ad-Aware.exe
Comments : All Rights Reserved
#:39 [urlmap.exe]
FilePath : C:\Program Files\Microsoft Money\System\
ProcessID : 3964
ThreadCreationTime : 9-25-2006 10:01:08 PM
BasePriority : Normal
FileVersion : 10.00.0809
ProductVersion : 10.00.0809
ProductName : Microsoft Money
CompanyName : Microsoft Corporation
FileDescription : Money URL Map
InternalName : URLMAP
LegalCopyright : Copyright © Microsoft Corp. 1990-2001. All rights reserved.
OriginalFilename : urlmap.exe
Memory scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 0
Started registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Registry Scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 0
Started deep registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Deep registry scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 0
Started Tracking Cookie scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : [removed][2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:4
Value : Cookie:[removed]/
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : owner@advertising[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:50
Value : Cookie:[removed]/
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : [removed][2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:7
Value : Cookie:[removed]/
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : [removed][2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:2
Value : Cookie:[removed]/
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : owner@2o7[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:3
Value : Cookie:[removed]/
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : [removed][2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:12
Value : Cookie:[removed]/
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : owner@zedo[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:7
Value : Cookie:[removed]/
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : [removed][1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:3
Value : Cookie:[removed]/
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : [removed][1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:8
Value : Cookie:[removed]/
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : owner@atdmt[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:9
Value : Cookie:[removed]/
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : owner@hitbox[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:14
Value : Cookie:[removed]/
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : owner@trafficmp[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:19
Value : Cookie:[removed]/
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : owner@mediaplex[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:7
Value : Cookie:[removed]/
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : [removed][1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:7
Value : Cookie:[removed]/
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : [removed][2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:3
Value : Cookie:[removed]/
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : owner@doubleclick[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:11
Value : Cookie:[removed]/
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : [removed][1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:2
Value : Cookie:[removed]/
Tracking cookie scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 17
Objects found so far: 17
Deep scanning and examining files (C:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Disk Scan Result for C:\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 17
Scanning Hosts file……
Hosts file location:"C:\WINDOWS\system32\drivers\etc\hosts".
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Hosts file scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
1 entries scanned.
New critical objects:0
Objects found so far: 17
Performing conditional scans…
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Conditional scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 17
3:20:37 PM Scan Complete
Summary Of This Scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Total scanning time:00:19:09.937
Objects scanned:153854
Objects identified:17
Objects ignored:0
New critical objects:17
Well it looks like all Adaware found were tracking cookies. Did you get rid of them?
these same tracking cookies return every single day, and they slow the computer way down. How do we stop them?
Hi Clint,
Here's what I would do. It works for me. I use Mozilla firefox as my browser
http://www.mozilla.com/
The following has an article about flaw in Internet Explorer and also mentions using Mozilla firefox.
http://www.updatexp.com/kb925568.html
You still must use Internet Explorer for Microsoft updates though.
Then to prevent those cookies that are plaguing you, install Spyware Blaster .
SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.
A tutorial on installing & using this product can be found here:
Using SpywareBlaster to protect your computer from Spyware and Malware
After you install SpywareBlaster, do the updates and enable all protection, click the Mozilla Firefox tab at the top and you will see all the cookies that are blocked.
Please let me know if this helps you.
Glad we could be of assistance.
This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.
Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.
Coyote's Installed programs for prevention:
http://forums.tomcoyote.org/index.php?showtopic=31418
The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.
Visit the CoyoteStore
http://TomCoyote.org/coyotestore.php